VYPR

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

BaseStableLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-209 · CAPEC-588 · CAPEC-591 · CAPEC-592 · CAPEC-63 · CAPEC-85

CVEs mapped to this weakness (46,817)

page 289 of 2,341
  • CVE-2026-54013HigJun 23, 2026
    risk 0.42cvss 7.6epss 0.00

    Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI patched SVG XSS in user profile images and webhook profile images but forgot to apply the same fix to model profile images. The ModelMeta class has no…

  • CVE-2026-55409HigJun 22, 2026
    risk 0.42cvss 7.6epss 0.00

    Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.53, a disabled RichEditor field rendered its raw state without sanitizing HTML. Where the data stored in this field's state isn't sanitized already when the form state was…

  • CVE-2026-48167MedJun 22, 2026
    risk 0.42cvss 6.4epss 0.00

    Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the ImageColumn and ImageEntry components render raw database values without escaping HTML. Where the data passed to these components isn't validated, an…

  • CVE-2026-12157MedJun 19, 2026
    risk 0.42cvss 6.4epss 0.00

    The BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blockId attribute of the betterdocs/category-slate-layout Gutenberg block in versions up to, and including, 4.5.3. This is…

  • CVE-2026-8039MedJun 18, 2026
    risk 0.42cvss 6.4epss 0.00

    The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' shortcode attribute in the 'testimonial' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2026-2021MedJun 18, 2026
    risk 0.42cvss 6.4epss 0.00

    The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortcode attribute in all versions up to, and including, 1.8.5. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This…

  • CVE-2026-12136MedJun 18, 2026
    risk 0.42cvss 6.4epss 0.00

    The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysbasics_user_avatar' shortcode in versions up to, and including, 4.3.6. This is due to insufficient input sanitization and output escaping on user supplied…

  • CVE-2026-12098MedJun 18, 2026
    risk 0.42cvss 6.4epss 0.00

    The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed' Episode Meta Field in all versions up to, and including, 11.16.8 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-11402MedJun 18, 2026
    risk 0.42cvss 6.4epss 0.00

    The Services Section Block – Showcase Service Details in Grid or Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'link' Block Attribute in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This…

  • CVE-2026-8494MedJun 17, 2026
    risk 0.42cvss 6.4epss 0.00

    The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admin URI Editor interface in all versions up to, and including, 2.5.3.3 due to insufficient output escaping. This makes it possible for authenticated attackers,…

  • CVE-2026-49773MedJun 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions.

  • CVE-2026-48880MedJun 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in WP Job Portal <= 2.5.2 versions.

  • CVE-2026-48870MedJun 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.62 versions.

  • CVE-2026-42688MedJun 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in Modula Image Gallery <= 2.14.23 versions.

  • CVE-2026-42663MedJun 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Simple Membership <= 4.7.2 versions.

  • CVE-2026-42656MedJun 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in Contest Gallery <= 28.1.6 versions.

  • CVE-2026-41556MedJun 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in ProfilePress <= 4.16.13 versions.

  • CVE-2026-39540MedJun 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in Shipment Tracker for Woocommerce <= 1.5.3.2 versions.

  • CVE-2026-39491MedJun 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in JupiterX Core <= 4.14.1 versions.

  • CVE-2025-15659MedJun 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in Elizaibots <= 1.0.2 versions.